Remote Code Execution Vulnerability in Backstage TechDocs by Spotify
CVE-2026-106510
7.7HIGH
What is CVE-2026-106510?
An issue exists in the @backstage/plugin-techdocs-node package affecting Backstage prior to version 1.14.6, where an authenticated user with the ability to register catalog entities can exploit crafted markdown extensions in the techdocs mkdocs.yml. This vulnerability allows for arbitrary operating system command execution on the TechDocs build host during the documentation build process.
Affected Version(s)
backstage < 1.50.5 < 1.50.5
backstage >= 1.51.0-next.0, < 1.54.6 < 1.51.0-next.0, 1.54.6
plugin-techdocs-node < 1.14.6 < 1.14.6
